← Back to Bookessa

Legal

Privacy Policy

This policy explains what personal data Bookessa collects, why we collect it, who we share it with and what rights you have over it. It covers our website, the Bookessa application and the booking pages our customers publish through us.

Last updated: 19 August 2026 Effective: 19 August 2026 Version: 1.0
Contents
  1. Who we are
  2. Controller and processor roles
  3. What we collect
  4. Why we use it and our legal bases
  5. Booking data and end customers
  6. Payments and billing
  7. The AI booking assistant
  8. Cookies and similar technologies
  9. Who we share data with
  10. International transfers
  11. How long we keep data
  12. How we protect data
  13. Your rights
  14. Children
  15. Changes to this policy
  16. How to contact us

1. Who we are

Bookessa provides online appointment booking software for service businesses. Businesses use Bookessa to publish a booking page, manage their availability and accept appointments from their own customers.

For the purposes of data protection law, the data controller for the personal data described in this policy is:

Detail
Value
Legal entity
[Registered company name]
Registered address
[Street, city, postal code, country]
Company number
[Registration number]
VAT number
[VAT number]
Contact
hello@bookessa.com

We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the GDPR. Privacy questions go to the contact address above and are handled by our team directly.

2. Controller and processor roles

Bookessa handles two different kinds of personal data, and our responsibilities differ for each. This distinction matters, because it determines who you should contact about your data.

We are the controller for account data

When a business signs up for Bookessa, we decide how and why we process the data of that business and its staff — account details, billing information, support conversations and usage logs. For this data we are the controller, and this policy governs it in full.

We are a processor for booking data

When a member of the public books an appointment through a booking page powered by Bookessa, the business receiving that booking decides why the data is collected and what happens to it. That business is the controller; Bookessa is a processor acting on its documented instructions.

If you booked an appointment and want your data corrected or deleted, contact the business you booked with. They control that record. If you contact us instead, we will pass your request to them and support them in answering it, but we cannot act on it independently.

Our processing on behalf of business customers is governed by a Data Processing Agreement, which forms part of our Terms of Service.

3. What we collect

We collect only what we need to run the service. We do not buy personal data from third parties, and we do not build advertising profiles.

Information you give us

  • Account details — your name, business name, email address and password. Passwords are stored only as salted hashes; we never see or store them in readable form.
  • Billing details — legal business name, billing email, billing address and, where you provide one, your VAT or tax identification number. These appear on the invoices issued for your subscription.
  • Workspace configuration — the services you offer, their duration and price, your availability, staff members and the content of your booking page.
  • Support correspondence — the content of emails and messages you send us, and our replies.

Information we collect automatically

  • Authentication and session data — sign-in events, verification codes and session tokens used to keep you signed in securely.
  • Technical data — IP address, browser type and version, device type, operating system, language and referring page.
  • Usage data — pages viewed, features used, and timestamps of significant actions such as publishing a booking page or changing a plan.
  • Diagnostic data — error reports and performance traces generated when something fails, which help us find and fix defects.

Information we receive from others

  • Payment status — from Stripe, our payment processor: whether a payment succeeded, the subscription state, plan and billing dates. Stripe may display the card brand and last four digits inside its secure billing portal; Bookessa does not store those card details in its application database. We never receive your full card number.
  • Email delivery status — from our email provider: whether a message was delivered, bounced or was marked as spam.

We do not intentionally collect special category data — health, biometrics, religion, political opinions or similar. Some businesses using Bookessa operate in health or wellness, and an appointment record may imply such information. Where that happens, the business is the controller and is responsible for establishing a lawful basis under Article 9 of the GDPR.

4. Why we use it and our legal bases

Under the GDPR we must have a lawful basis for every use of personal data. The table below sets out each purpose, the data involved and the basis we rely on.

Purpose
Legal basis
Creating and running your account
Performance of a contract (Art. 6(1)(b)) — we cannot provide the service without it.
Taking payment and issuing invoices
Performance of a contract (Art. 6(1)(b)), and legal obligation (Art. 6(1)(c)) for tax and accounting records.
Hosting bookings on behalf of a business
Processed on the business's instructions; the business establishes its own basis. Our role is set by contract (Art. 28).
Service emails — receipts, security alerts, changes
Performance of a contract (Art. 6(1)(b)). You cannot opt out of these while you hold an account.
Securing the service and preventing abuse
Legitimate interests (Art. 6(1)(f)) — keeping accounts and data safe from unauthorised access.
Improving and debugging the product
Legitimate interests (Art. 6(1)(f)) — we use aggregated and minimised data wherever it is sufficient.
Marketing emails to prospects
Consent (Art. 6(1)(a)), withdrawable at any time via the unsubscribe link in every message.
Defending or bringing legal claims
Legitimate interests (Art. 6(1)(f)) and, where applicable, legal obligation (Art. 6(1)(c)).

Where we rely on legitimate interests, we have assessed that interest against your rights and freedoms and concluded that our processing does not override them. You may object to any such processing — see Your rights.

5. Booking data and end customers

If you booked an appointment through a Bookessa-powered page, the business you booked with decides what information to request. Typically this includes your name, email address, telephone number, the service booked, the appointment time and any note you add.

We store that information so the business can manage the appointment, and we send booking confirmations and reminders on their behalf. We do not use booking data to market to you, we do not sell it, and we do not use it to train AI models that serve other businesses.

Exercising your rights over a booking: contact the business directly — their name and contact details appear on the booking page and in your confirmation email. We will help them respond within the statutory deadline.

6. Payments and billing

Subscription payments are processed by Stripe Payments Europe, Ltd. Card details are entered directly into Stripe's payment form and are transmitted to Stripe, not to us. Bookessa never receives, stores or has access to your full card number, expiry date or security code.

We receive and store a Stripe customer identifier, your subscription status, plan, trial and renewal dates. We use these to show your billing state in the app, reconcile payments and issue invoices. Stripe may show the card brand and last four digits in its secure billing portal, but Bookessa does not store those card details in its application database.

The billing details you enter at checkout — legal name, address and any VAT number — are passed to Stripe so it can produce a valid invoice and calculate tax correctly. Stripe acts as an independent controller for payment processing and applies its own privacy notice, available at stripe.com/privacy.

We retain invoices and the underlying billing records for the period required by tax law in our country of establishment — see How long we keep data.

7. The AI booking assistant

Businesses on our Premium and Pro plans may enable an AI booking assistant that answers questions and takes bookings in conversation on their website.

  • The assistant answers from the information the business has approved — its services, prices, availability and its own question-and-answer content.
  • Conversation content is processed to generate a reply and is retained so the business can review its own conversations.
  • We do not use conversations from one business to train models used by another, and we do not use your conversations to train third-party foundation models.
  • Automated replies are not a decision producing legal or similarly significant effects within the meaning of Article 22 of the GDPR. A booking is always confirmed against the business's real availability, and a human at the business can review, change or cancel any appointment.

Please avoid entering sensitive personal information into the assistant. If you need to share something confidential, contact the business directly.

8. Cookies and similar technologies

We keep our use of cookies deliberately narrow. We do not run third-party advertising cookies and we do not track you across other websites.

Category
What it does
Strictly necessary
Keeps you signed in, remembers your session and protects forms against cross-site request forgery. These cannot be switched off, and no consent is required for them.
Preferences
Remembers choices such as the plan you were viewing, so the interface behaves predictably when you return.
Analytics
Aggregated measurement of which pages and features are used, so we can prioritise work. Set only where you have consented, if and when we enable it.

Your browser lets you block or delete cookies. Blocking strictly necessary cookies will prevent you from signing in. Where we rely on consent for a cookie, you can withdraw it at any time and we will stop setting it.

We honour the Global Privacy Control signal where your browser sends one.

9. Who we share data with

We do not sell personal data. We share it only with the service providers we need to run Bookessa, each bound by a contract that limits them to acting on our instructions.

Recipient
Purpose
Supabase
Database hosting, authentication and backend functions. Hosted in the EU.
Stripe
Payment processing, subscription management, invoicing and tax calculation.
Email delivery provider
Sending verification codes, booking confirmations, reminders and service notices.
AI model provider
Generating assistant replies for businesses that enable the feature. Bound not to train on submitted content.
Hosting and CDN
Serving the website and application, and absorbing malicious traffic.

We may also disclose personal data where we are required to:

  • to comply with a binding legal obligation, court order or lawful request from a public authority;
  • to establish, exercise or defend legal claims, or to enforce our Terms of Service;
  • to protect the rights, property or safety of Bookessa, our customers or the public, including preventing fraud and abuse;
  • to a buyer or successor in the event of a merger, acquisition or sale of assets — in which case we will notify you before your data becomes subject to a different privacy policy.

Where a request from an authority appears unlawful, overbroad or improperly served, we will challenge it. Where we are legally permitted to tell you about it, we will.

10. International transfers

We aim to keep personal data within the European Economic Area. Our primary database and application infrastructure are hosted in the EU.

Some of our providers are established outside the EEA, or may access data from outside it for support purposes. Where personal data is transferred outside the EEA, we rely on one of the following safeguards under Chapter V of the GDPR:

  • an adequacy decision by the European Commission covering the destination country; or
  • the European Commission's Standard Contractual Clauses, combined with a transfer impact assessment and, where appropriate, additional technical measures such as encryption in transit and at rest.

You may request a copy of the safeguards we rely on by writing to hello@bookessa.com.

11. How long we keep data

We keep personal data only as long as we need it for the purpose it was collected, or as long as the law requires.

Data
Retention period
Account and workspace data
For as long as your account is open, then deleted within 90 days of closure.
Booking records
For as long as the business keeps them, or until the business deletes them or closes its account. Deleted within 90 days of account closure.
Invoices and accounting records
[Typically 7–10 years] as required by tax law in our country of establishment, even after your account closes.
Security and audit logs
12 months, then deleted or irreversibly aggregated.
Support correspondence
24 months from the last message in the conversation.
Backups
Rolling 35-day cycle. Deleted records disappear from backups as the cycle turns over.
Marketing contacts
Until you unsubscribe, then a minimal suppression record is kept so we do not contact you again.

Where we must retain a record for legal reasons, we restrict access to it rather than continuing to use it actively.

12. How we protect data

We take appropriate technical and organisational measures under Article 32 of the GDPR, including:

  • Encryption — TLS for all data in transit, and encryption at rest for the database and backups.
  • Access control — row-level security so each workspace can reach only its own records, and least-privilege access for our staff.
  • Credential hygiene — passwords stored as salted hashes, and email verification codes that expire.
  • Isolation of payment data — card details go directly to Stripe and never touch our servers.
  • Backups and recovery — regular encrypted backups with tested restoration.
  • Monitoring — logging of authentication and administrative events to detect unusual activity.

No system is perfectly secure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and we will inform you directly without undue delay where the risk is high.

13. Your rights

If the GDPR applies to you, you have the following rights over personal data for which we are the controller.

  • Access — obtain confirmation of whether we process your data, and a copy of it.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure — have your data deleted where we no longer have grounds to keep it.
  • Restriction — have us pause processing while a dispute about accuracy or legitimacy is resolved.
  • Portability — receive the data you gave us in a structured, machine-readable format, and have it sent to another provider where technically feasible.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time. We will stop marketing immediately on request.
  • Withdraw consent — where we rely on consent, withdraw it at any time. This does not affect processing carried out before withdrawal.
  • Complain — lodge a complaint with your local data protection supervisory authority. Our lead authority is [Supervisory authority of the country of establishment].

To exercise any of these, email hello@bookessa.com. We respond within one month, extendable by two further months for complex requests — we will tell you if that happens and why. We may ask for information to verify your identity, and we will not charge a fee unless a request is manifestly unfounded or excessive.

14. Children

Bookessa is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16 for the purposes of creating an account.

A business using Bookessa may take an appointment for a minor — for example a paediatric clinic or a children's class. In that case the business is the controller and is responsible for obtaining any parental consent required by local law.

If you believe a child has provided us with personal data for which we are the controller, contact us and we will delete it.

15. Changes to this policy

We may update this policy as the service evolves or the law changes. The "last updated" date at the top always reflects the current version.

For material changes — a new purpose, a new category of recipient, or a change that reduces your rights — we will give account holders at least 30 days' notice by email or in-app before the change takes effect. Continuing to use Bookessa after that period means the updated policy applies. If you disagree, you may close your account before it takes effect.

16. How to contact us

For any privacy question, request or complaint, write to hello@bookessa.com with "Privacy" in the subject line, or by post to the registered address in section 1.

We would rather resolve a concern directly than have you go to a regulator, but you always have the right to complain to your supervisory authority without contacting us first.

This policy is provided in English. Where we publish a translation and the versions conflict, the English version governs. If any provision is found unenforceable, the remainder continues to apply.